Re: [PATCH nf] netfilter: nat: force port remap to prevent shadowing well-known ports

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > We could avoid the rewrite for connections that are not being forwarded,
> > but get_unique_tuple() and the callers don't propagate the required hook
> > information for this.
> 
> Probably you can scratch a bit to store in the struct nf_conn object
> if this is locally generated flows?

Yes, that's doable.



[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux